GNOME espeaker Local Buffer Overflow Vulnerability
BID:663
Info
GNOME espeaker Local Buffer Overflow Vulnerability
| Bugtraq ID: | 663 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-1477 |
| Remote: | No |
| Local: | No |
| Published: | Sep 26 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was found by Brock Tellier <[email protected]>. |
| Vulnerable: |
Mandriva Linux Mandrake 6.0 GNOME Gnome Libs 1.0.8 |
| Not Vulnerable: |
GNOME Gnome Libs 1.0.15 |
Discussion
GNOME espeaker Local Buffer Overflow Vulnerability
A buffer overflow vulnerabilityin GNOME's shared libraries handling of the 'espeaker' command line argument may allow local users to attack setuid binaries linked against these libraries to obtain root access.
Calling a program linked against GNOME with the command like arguments '--enable-sound --espeaker=<80 byte buffer>' results in a buffer overflow.
One known setuid root program linked against these libraries in the Mandrake 6.0 distribution is '/usr/games/nethack'.
It is likely this is a vulnerability in the libesd shared library instead of libgnome. In that case esound 0.2.8 would be vulnerable.
A buffer overflow vulnerabilityin GNOME's shared libraries handling of the 'espeaker' command line argument may allow local users to attack setuid binaries linked against these libraries to obtain root access.
Calling a program linked against GNOME with the command like arguments '--enable-sound --espeaker=<80 byte buffer>' results in a buffer overflow.
One known setuid root program linked against these libraries in the Mandrake 6.0 distribution is '/usr/games/nethack'.
It is likely this is a vulnerability in the libesd shared library instead of libgnome. In that case esound 0.2.8 would be vulnerable.